Skip to content
Guides

Does Cyber Essentials require a VPN?

No. Cyber Essentials does not mandate a VPN. Apply the scheme rules to each in-scope remote administration path, boundary firewall, account and cloud service; a VPN is one possible design.

person using black laptop computer

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Does Cyber Essentials require a VPN?

No - Cyber Essentials does not require a VPN. Under v3.3, check the applicable requirements for in-scope accounts, remote administration and boundary firewalls. A VPN may be useful, but its presence alone does not establish a pass.

Section 02

What v3.3 actually requires for remote access

  • Apply MFA to in-scope cloud services and to remote administration where the current scheme criteria require it; check each account and service.
  • Restrict and document internet-facing access and remote administration under the firewall and secure-configuration rules.
  • Use suitable encrypted transport and stronger authentication where appropriate. TLS 1.2 and phishing-resistant MFA are useful design choices, but not universal stand-alone Cyber Essentials mandates.

See the User Access Control pillar guide for the full detail.

Section 03

Where a VPN is a good solution

  • Accessing on-premises servers or file shares from outside the office.
  • Presenting a consistent egress IP for allow-listing.
  • Protecting traffic on untrusted networks.
  • Legacy applications that assume a trusted LAN.

A VPN can be part of a compliant design when the in-scope endpoints, accounts, firewalls and services also meet their applicable requirements.

Section 04

Where a VPN is not needed

Cloud-first organisations that access all corporate services through Microsoft 365, Google Workspace, or SaaS tools - with identity-provider MFA enforced via Conditional Access - may meet the applicable account controls without a VPN. Their endpoints and any exposed management services still need separate checks.

This is increasingly common for:

  • SaaS SMEs with no internal infrastructure
  • Fully remote-first businesses using Zero Trust / conditional-access patterns
  • Organisations that have already retired legacy LAN-dependent applications

Section 05

Where Conditional Access helps without a VPN

Microsoft Entra ID Conditional Access, Okta, and Google Workspace Context-Aware Access can enforce:

  • MFA per sign-in
  • Device-compliance requirement (MDM-enrolled, encrypted, patched)
  • Risk-based blocks for unusual locations or impossible travel
  • Phishing-resistant MFA for admin roles

Configured properly, this provides stronger authentication and authorisation than a traditional VPN with a shared password plus one-time code. It helps with identity enforcement but does not replace boundary firewall or endpoint checks.

Section 06

VPN rules that still apply to remote workers

Regardless of whether a VPN is in place:

  • Organisation-issued home-office routers are in scope; ordinary privately owned home routers are outside the boundary, while work devices remain in scope.
  • MFA on email and cloud services is required for everyone.
  • Use stronger, phishing-resistant MFA for admin accounts where supported; check the actual scheme requirement for each service.

See Cyber Essentials for remote and hybrid workforces for the complete remote-work scope.

Section 07

Bottom line

Cyber Essentials does not require a VPN. Check the actual account, remote-administration, firewall and endpoint criteria. VPN and Conditional Access can each help, but neither architecture alone guarantees a pass.

Start Cyber Essentials from £299.99 + VAT | MFA for Cyber Essentials v3.3 | Free readiness check

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group